If SSO authentication is allowed when you make a Helix appliance Web UI page request (through an application or by entering the appliance URL in the browser address bar), you can choose between local login and single sign-on authentication. You can also log in to the Web UI for certificate authentication. For details about certificate authentication, see Common Access Card (CAC) for certificate authentication.
Logging in when SSO Is allowed
If no session to the requested Helix appliance exists when you make a Web request for a Web UI page on that appliance, the login page offers two ways to log in to the appliance:

The login page also offers three ways to log in to the appliance if both a certificate and SSO are optional for user authentication:

Logging In to the Appliance
If you use the standard login, you enter your local credentials for the appliance, and the Web UI session is valid only for this appliance. To view the Web UI pages on other Helix appliances, you must log in locally at the Web UI of each appliance.
Logging In Using SSO
If you click Sign In Using Single Sign‑On, the Trellix Cloud Account login page appears, and you enter your Trellix IAM account credentials. The Alerts page of the requested appliance appears. To view Web UI pages of other Helix appliances, you do not need to log in again, as long as the SSO session has not expired.

Logging out when SSO is allowed
If SSO is allowed, the logout sequence depends on whether you logged in locally used SSO authentication.
If you logged In locally
If you logged in locally, you log out using the local logout dialog box.

If you logged in with Single Sign‑On authentication
If you logged in with SSO authentication, you log out using the single sign-on logout dialog box.

After you click Logout, your session is closed and the dual login page appears again.

Note
The log out message will not be displayed if it is disabled. Use the aaa authentication logout user-message enable command to display the log out message. For details about how to enable the log out message setting, see Enabling or disabling the log out message setting using the CLI.